QuarterFile

We’ll email you the day it opens

Filing opens for the 7 February 2027 quarter. No account, no card.

We store your email address to tell you when QuarterFile opens, and to send one reminder before each quarterly deadline, until you unsubscribe. Nothing else. How we handle your data.

Cookies and local storage

Last updated: 21 July 2026

The short version: no marketing or advertising cookies, no third-party analytics, no ad pixels, no tag managers, no tracking across other sites. The only third-party code we load is Google reCAPTCHA Enterprise, and only to confirm a form submission isn’t automated: we use the single token it issues solely to verify that submission. What the app does store on your device is listed below: most of it exists to keep you signed in, to satisfy HMRC’s legal fraud-prevention requirements, or to remember what you’ve already dismissed. The one non-essential item (time measurement) is off until you choose to turn it on, which is why there is no cookie banner: there is nothing here to consent to by default.

WhatTypePurposeLifetime
Sign-in sessionBrowser storage (IndexedDB)Keeps you signed in securely between visitsUntil sign-out
qf.deviceIdLocal storageA random device identifier HMRC legally requires with every filing (fraud prevention). Created once, used only when talking to HMRC.Until you clear browser data
qf.tot.*Local storageOnly written if you switch time measurement on. Measures your own active preparation time and typed/imported line counts for the quarter you’re working on, shown back to you on your receipt (“this quarter took you N minutes”). First-party only; never advertising.Cleared when the quarter is filed, or when you switch measurement off
qf.hint.* / qf.endScreen.* / qf.tasteOverLoggedLocal/session storageRemembers which in-app tips you dismissed so they never reappear, which end-of-filing screen you last saw, and that we’ve already noted a one-off in-app message this sessionUntil you clear browser data (the session ones, until you close the tab)
Google reCAPTCHA EnterpriseCookies and script, from GoogleLoads on our forms only to confirm a submission isn’t automated. We use the token it issues solely to verify that submission.Set by Google while the check runs
HMRC connection handoffCookieSet when you start the HMRC connection and checked when HMRC sends you back, so only the browser that began the connection can finish it.15 minutes
Stripe (checkout only)Cookies, on Stripe’s pagesFraud prevention during paymentSet by Stripe at checkout

The time measurement (qf.tot.*) is off unless you turn it on. It isn’t needed to run the app: nothing is stored and nothing is measured until you switch it on in Settings, under “Your data”. Switch it off again whenever you like, and measuring stops there and then. It exists because a receipt that says “this quarter took you 11 minutes” should be your own measured number.

Separately from all of this, HMRC legally requires certain device information when we file to their APIs. That’s explained in the fraud-prevention section of our privacy policy.